Coldcard Firmware Flaw Costs Over $71M in BTC
A software flaw in Coldcard's firmware allowed attackers to reconstruct private keys and steal more than $71 million in BTC, the wallet's maker Coinkite has revealed. The company blamed the discovery partly on artificial intelligence (AI), but critics say that AI is not entirely to blame.
The bug was discovered after roughly 594 BTC ($38 million) moved from about 500 single-signature addresses on July 30. Researchers estimated that between 1,082 and 1,196 addresses may have been affected during a period of about 41 minutes. A custom dashboard called Coldcard Sweep Watch placed the total at 1,128.4717 BTC, worth around $71.1 million when bitcoin traded near $63,044.
The weakness was linked to seeds created on Coinkite's Mk3 devices running firmware version 4.0.1 and later versions. The company released emergency firmware fixes, but users with affected seeds must create new wallets on fixed firmware.